Rewterz
Rewterz Threat Advisory – ICS: Multiple Siemens SIMATIC NET CP Vulnerability
August 11, 2021
Rewterz
Rewterz Threat Advisory –Multiple Microsoft Security Vulnerabilities
August 11, 2021

Rewterz Threat Alert – Kimsuky APT Group – Active IOCs

Severity

High

Analysis Summary

The North Korean advanced persistent threat (APT) group Kimsuky has been found to be distributing a fake Korean Internet and Security Agency (KISA) app via malicious emails. A mobile malware researcher has shared information about a fake KISA vaccine or security android app disguised as the KISA security program. When the target downloads the APK implanted file from the email and installs the application on his device, the malicious code does its job. It executes in the background without the target’s knowledge and collects sensitive information from his device.

advisory-1628682191.png

Impact

  • Watering hole attacks
  • Keyloggers
  • Remote Access Connections

Indicators of Compromise

Filename

  • BIOStyle[.]dotm

MD5

  • 863fd86868014b5cc008764816c422c5

SHA-256

  • c4830cabdaeedcef3cdb771e96dca5f46228a095341aec275deee7fd51fc789b

SHA-1

  • 226d9db018302cb3a16b0c403dc912c863454daa

URL

  • http[:]//vnskwl[.]mypressonline[.]com/relationship/BIOStyle[.]dotm
  • http[:]//outwd[.]myartsonline[.]com/yu/ls[.]txt

Remediation

  • Search for IOCs in your environment.
  • Block all threat indicators at their respective controls.
  • Always be suspicious about emails sent by unknown senders.